Multi-Factor Authentication (MFA) adds an additional layer of security to your Haiilo account by requiring a second verification factor during sign-in.
Instead of relying solely on a password, users must also provide a verification code generated by an authenticator application. This significantly reduces the risk of unauthorized account access, even if a password becomes compromised.
This feature is available as part of the Advanced Security Add-on. Please contact your personal Account Manager for further information.
This article describes a preview version of the feature. Functionality, screen layouts, terminology, and behavior may change before the final release.
Some planned administrative capabilities are not yet available in the current preview build, but are expected to be included before the feature becomes generally available.
What is Multi-Factor Authentication?
Multi-Factor Authentication (MFA) adds a second layer of verification during sign-in. After entering a username and password, users must also provide a time-based verification code generated by an authenticator application.
This additional verification step helps protect accounts even if passwords are compromised, significantly reducing the risk of unauthorized access.
Any authenticator application that supports industry-standard Time-based One-Time Passwords (TOTP) can be used. Popular options include:
- Microsoft Authenticator
- Google Authenticator
- 1Password
- Authy
- Other compatible TOTP authenticator applications
How do I enable MFA?
Users can enable MFA directly within their account settings.
- Open Account Settings.
- Navigate to the Multi-Factor Authentication (MFA) section.
- Select Enable.
- Re-enter your password to confirm your identity.
- Scan the displayed QR code using your preferred authenticator app.
- Alternatively, enter the provided secret key manually.
- Enter the verification code generated by your authenticator app.
- Optionally assign a name to the device.
- Complete the setup process.
Once setup is complete, the registered MFA device will be displayed in your account settings.
How does signing in work?
After MFA is enabled, users are prompted for an additional verification code during sign-in.
- Enter your username and password.
- Enter the verification code generated by your authenticator application.
- Complete the sign-in process.
After a successful MFA verification, users can choose to trust the current device.
When a device is trusted, MFA verification will not be required again in the same browser on that device. The trusted status applies only to the specific browser and device combination and can be revoked at any time from Account Settings.
This provides a smoother login experience on regularly used devices while maintaining strong account security.
Managing trusted devices
All trusted devices can be reviewed within Account Settings.
Users can view their trusted devices, remove devices that are no longer used, or revoke trust for a device at any time. Once trust has been removed, MFA verification will be required again during the next login from that device.
Additional administrative capabilities
The current preview focuses on self-service MFA enrollment and authentication for end users.
Additional administrative capabilities are planned before general availability, including MFA recovery and the ability to enforce MFA for all users or selected user groups.
Frequently asked questions
- Any authenticator application that supports industry-standard Time-based One-Time Passwords (TOTP) should work. Examples include Microsoft Authenticator, Google Authenticator, 1Password, and Authy.
- No. If scanning the QR code is not possible, you can manually enter the provided secret key into your authenticator application.
- Not necessarily. If you choose to trust a device, future logins from that browser on the same device may not require MFA verification.
- Yes. Trusted devices can be reviewed and removed from Account Settings at any time.
- Administrative MFA reset and recovery capabilities are planned as part of the final release. Once available, administrators will be able to assist users who no longer have access to their registered authenticator device.
- Not in the current preview version. However, enforcement capabilities for all users or selected user groups are planned and are expected to be available before the final release.
Security best practices
To get the most benefit from MFA, Haiilo recommends:
- Enable MFA whenever possible.
- Protect access to your authenticator application.
- Never share verification codes.
- Remove trusted devices you no longer use.
- Secure your mobile device with a PIN, biometrics, or both.
- Report suspected unauthorised account activity immediately.